Privacy Policy
Last updated: July 2026
1. Information We Collect
Account information: name, email address, and password (hashed) when you register. Restaurant information: venue name, address, phone, hours, menu content, photos, and integration credentials you provide. Usage data: anonymous page views (path, referrer, per-session random identifier) collected on restaurant public pages. Payment data: processed by Stripe; we do not store your full card number.
2. Cookies We Use
Tabern uses only strictly necessary and functional cookies:
- tabern.auth.session — your signed-in session. HttpOnly and Secure in production.
- tabern.csrf — protects your account against cross-site request forgery. Required to stay signed in securely.
- cookie-consent — remembers your choice on the cookie notice.
- tabern-color-mode — remembers your light/dark theme preference.
- tabern-locale — remembers your language preference.
We do not use third-party advertising or tracking cookies.
3. Analytics
Restaurant pages record anonymous, first-party page views (page path, referrer, and a per-browser-session random identifier) on our own servers to show restaurant owners how their site performs. No data is shared with third-party analytics providers. Analytics are opt-in — no tracking occurs until you click "Accept" on the cookie notice. You can change your preference at any time from the cookie preferences link in the footer.
4. How We Use Your Information
We use your information to: (a) operate and maintain your restaurant website; (b) process subscription payments; (c) provide customer support; (d) improve the Service; and (e) comply with legal obligations. We do not sell your personal information to third parties.
5. Data Sharing
We share data with our service providers only as needed to operate the Service: Stripe (payments), Square (menu sync, if enabled), OpenAI (menu scanning, if used), Mailgun (transactional email), and our hosting provider. Each provider processes data under their own privacy policy and data processing agreement. We may disclose information when required by law or to protect our rights.
6. Data Retention
We retain your account and restaurant data for as long as your account is active. After account deletion, we remove your data within 30 days, except where retention is required by law (e.g., financial records). Anonymous analytics data is retained for up to 24 months.
7. Your Rights (GDPR / CCPA)
If you are in the EU/UK or California, you have the right to: (a) access your personal data; (b) request correction or deletion; (c) request data portability; (d) object to processing; and (e) withdraw consent at any time. To exercise these rights, contact us at privacy@tabern.app. We respond within 30 days.
8. Security
We use industry-standard measures to protect your data, including TLS encryption in transit, hashed passwords (ASP.NET Identity), HttpOnly/Secure session cookies, and CSRF protection. No method of transmission or storage is 100% secure. We will notify affected users of any data breach within 72 hours of discovery, as required by GDPR.
9. Children's Privacy
The Service is not directed to children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, contact us and we will delete it.
10. International Transfers
Your data may be processed in the United States or other countries where our service providers operate. We rely on Standard Contractual Clauses or equivalent safeguards for transfers from the EU/UK to third countries, as required by GDPR.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be posted on this page with an updated "Last updated" date. Continued use of the Service after changes constitutes acceptance of the revised policy.
12. Contact
Questions about this policy? Contact us through your account help page or at privacy@tabern.app. For data protection inquiries, you may also contact your local data protection authority.